CVE-2026-33678 is a high-severity vulnerability (CVSS 8.1) in Vikunja, an open-source task management platform, affecting versions prior to 2.2.1. This flaw allows any authenticated user to bypass authorization checks and download or delete any attachment in the system by providing a valid attachment ID, due to `TaskAttachment.ReadOne()` incorrectly querying attachments. The vulnerability has high confidentiality and integrity impacts, with low attack complexity and trivial enumeration of sequential attachment IDs. There is no evidence of active exploitation, nor are public exploit tools available, though it has received minor community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.2.1CPE matchmatch criteria | cpe:2.3:a:vikunja:vikunja:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.